-
Tue Dec 09 2025 Michel Lind <salimma@fedoraproject.org> - 4.2.27-1
- Update to version 4.2.27
- Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column
aliases on PostgreSQL
- Fixes CVE-2025-64460: Potential denial-of-service vulnerability in XML
Deserializer
- Fixes CVE-2025-64459: Potential SQL injection via _connector keyword
argument (4.2.26)
- Fixes CVE-2025-59681: Potential SQL injection in QuerySet.annotate(),
alias(), aggregate(), and extra() on MySQL and MariaDB (4.2.25)
- Fixes CVE-2025-59682: Potential partial directory-traversal via
archive.extract() (4.2.25)
- Fixes CVE-2025-57833: Potential SQL injection in FilteredRelation column
aliases (4.2.24)
-
Mon Jul 21 2025 Michel Lind <salimma@fedoraproject.org> - 4.2.23-1
- Update to version 4.2.23
- Strengthens fix for CVE-2025-48432
-
Sun Jun 08 2025 Michel Lind <salimma@fedoraproject.org> - 4.2.22-1
- Update to version 4.2.22
- Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags()
- Fixes CVE-2025-48432: Potential log injection via unescaped request path
- Revert pyproject conversion; we don't need it and don't have the needed
version
- Rebase Python 3.13 patch
-
Sat Mar 08 2025 Michel Lind <salimma@fedoraproject.org> - 4.2.20-1
- Update to version 4.2.20; Fixes: RHBZ#2350882
- Fix for CVE-2025-26699: Potential denial-of-service vulnerability in
django.utils.text.wrap()
-
Sat Jan 18 2025 Fedora Release Engineering <releng@fedoraproject.org> - 4.2.16-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
-
Wed Sep 04 2024 Michel Lind <salimma@fedoraproject.org> - 4.2.16-1
- Update to version 4.2.16
- Fixes: CVE-2024-45230, RHBZ#2309747
-
Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.2.14-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
-
Wed Jul 10 2024 Michel Lind <salimma@fedoraproject.org> - 4.2.14-1
- Update to 4.2.14 to address multiple CVEs
- resolves CVE-2024-38875, CVE-2024-39329, CVE-2024-39330, CVE-2024-39614
-
Fri Jun 28 2024 Python Maint <python-maint@redhat.com> - 4.2.11-3
- Rebuilt for Python 3.13
-
Thu Apr 11 2024 Michel Lind <salimma@fedoraproject.org> - 4.2.11-2
- Disable flaky tests that throw UnicodeEncodeError inconsistently